On Friday, the U.S. Justice Department announced that the now-arrested alleged administrator of the infamous hacking forum BreachForums facilitated the sale and purchase of private information that belonged to “millions of U.S. citizens and hundreds of U.S. and foreign companies, organizations, and government agencies.”
In a statement, prosecutors confirmed the arrest of Conor Fitzpatrick, 20, aka Pompompurin, of Peekskill, New York. Fitzpatrick is charged with one count of conspiracy to commit access device fraud, subject to a maximum of five years in prison if convicted.
The feds collected several pieces of evidence to nab Pompompurin
- the IP addresses that Pompompurin used to access RaidForums, the predecessor of BreachForums
- Pompompurin old email exposed in a data breach
conorfitzpatrick02@gmail.com
later confirmed by records from Google - Google Pay accounts linked to both that email address as well as a newer one,
conorfitzpatrick2002@gmail.com
both linked to a number owned by Fitzpatrick - records from Google showed
conorfitzpatrick2002@gmail.com
had a recovery email addressfunmc59tm@gmail.com
linked to an IP address registered to someone with the last name Fitzpatrick and a different phone number (his father) - Pompompurin used several VPNs to connect to his Gmail account
- records from Purse(dot)io revealed that four of the VPN IP addresses used to connect to the exchange were also used to connect to the
conorfitzpatrick2002@gmail.com
- another VPN IP address was also used to log into a Zoom account under the name “pompompurin” associated with a Riseup email address
- records from Purse(dot)io also showed he made purchased and shipped them to his address with the phone number
- 7 out of 9 IP addresses used to connect to Purse(dot)io were also used to connect to Pompompurin’s account on RaidForums
- Pompompurin accessed his account from an IP address registered to Fitzpatrick’s father at the same home address
- same IP address was used to access an iCloud account associated with Fitzpatrick
- FBI obtained a warrant to get Fitzpatrick’s real-time cell phone GPS location from Verizon, allowing agents to observe that Pompompurin was logged in to BreachForums while his phone’s location showed he was at his home.
Justice Department Announces Arrest of the Founder of One of the World’s Largest Hacker Forums and Disruption of Forum’s Operation
The founder of BreachForums made his initial appearance today in the Eastern District of Virginia on a criminal charge related to his alleged creation and administration of a major hacking forum and marketplace for cybercriminals that claimed to have more than 340,000 members as of last week. In...
www.justice.gov